US2011145563A1PendingUtilityA1

Secured file-based application programming interface

Assignee: KAIN MICHAEL THOMASPriority: Dec 14, 2009Filed: Dec 14, 2009Published: Jun 16, 2011
Est. expiryDec 14, 2029(~3.4 yrs left)· nominal 20-yr term from priority
H04L 69/163H04L 69/162H04L 63/0428H04L 63/166
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Data communication security systems and methods are disclosed. One such system includes a network interface configured for transport layer protocol communications at a communication port. The network interface includes a security module communicatively connected to a transport layer data path. The system further includes a file-based application programming interface defining a plurality of attributes of the network interface and including at least one attribute associated with data encryption managed by the security module and accessible for use in logical I/O operations.

Claims

exact text as granted — not AI-modified
1 . A data communication security system comprising:
 a network interface configured for transport layer protocol communications at a communication port, the network interface including a security module communicatively connected to a transport layer data path;   a file-based application programming interface defining a plurality of attributes of the network interface and including at least one attribute associated with data encryption managed by the security module and accessible for use in logical I/O operations.   
     
     
         2 . The data communication security system of  claim 1 , wherein the network interface includes a transport layer communication module. 
     
     
         3 . The data communication security system of  claim 2 , wherein the transport layer communication module further includes a security module. 
     
     
         4 . The data communication security system of  claim 3 , wherein the security module is communicatively connected to a file handler configured to control logical I/O operations. 
     
     
         5 . The data communication security system of  claim 1 , wherein the security module provides encryption of data communicated on a TCP data path. 
     
     
         6 . The data communication security system of  claim 1 , wherein at least one attribute specifies that the connection be secure or unsecure. 
     
     
         7 . The data communication security system of  claim 6 , wherein the implicit encryption mode uses a predetermined communication port number to enable encryption at the network interface. 
     
     
         8 . The data communication security system of  claim 6 , wherein the explicit encryption mode allows selectable enabling and disabling of encryption at the network interface. 
     
     
         9 . The data communication security system of  claim 1 , wherein the data encryption includes at least one of an SSL encryption protocol or a TLS encryption protocol. 
     
     
         10 . The data communication security system of  claim 1 , wherein the attribute associated with data encryption is accessible at a file handler. 
     
     
         11 . The data communication security system of  claim 10 , wherein the attribute associated with data encryption can be set to provide encryption of data associated with logical I/O operations. 
     
     
         12 . The data communication security system of  claim 1 , wherein the file-based application programming interface includes a plurality of attributes associated with data encryption and useable to configure encryption parameters used by the communication port. 
     
     
         13 . A method of securing data at a communication port of a computing system, the method comprising:
 issuing an open command to a communication port, the open command included in a file-based application programming interface defining a plurality of attributes including at least one attribute associated with data encryption;   setting at least one attribute of the communication port associated with data encryption at the communication port; and   issuing a write command to the communication port, the write command included in the file-based application programming interface, wherein data associated with the write command is encrypted based on the at least one attribute.   
     
     
         14 . The method of  claim 13 , further comprising issuing a read command to the communication port, the read command included in the file-based application programming interface, and wherein the data received at the communication port is encrypted based on the at least one attribute. 
     
     
         15 . The method of  claim 13 , wherein setting the at least one attribute to a predetermined value provides encryption of data associated with logical I/O operations 
     
     
         16 . The method of  claim 13 , wherein the data encryption includes at least one of an SSL encryption protocol or a TLS encryption protocol. 
     
     
         17 . The method of  claim 13 , wherein the file-based application programming interface includes a plurality of attributes associated with data encryption and useable to configure encryption parameters used by the communication port. 
     
     
         18 . The method of  claim 13 , wherein the at least one attribute includes an attribute capable of selecting at least one of an implicit encryption mode or an explicit encryption mode. 
     
     
         19 . The method of  claim 13 , wherein the at least one attribute denotes one or more ciphers to be used by the communication port. 
     
     
         20 . A communication interface for a computing system comprising:
 a network interface for transport layer protocol communications at a communication port, the network interface including a data path, a logical I/O control module communicatively connected to the data path, and a security module communicatively connected to the data path, the security module also communicatively connected to the logical I/O control module,   a file-based application programming interface defining a plurality of attributes of the network interface, the plurality of attributes including at least one attribute associated with data encryption managed by the security module and accessible for use in logical I/O operations, the at least one attribute defining at least one of an implicit encryption mode or an explicit encryption mode.

Join the waitlist — get patent alerts

Track US2011145563A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.